US2024333529A1PendingUtilityA1

Authenticating Data Based on Certificates

Assignee: SICK AGPriority: Mar 31, 2023Filed: Feb 27, 2024Published: Oct 3, 2024
Est. expiryMar 31, 2043(~16.6 yrs left)· nominal 20-yr term from priority
H04L 9/30H04L 9/3247H04L 9/3263H04L 9/3265H04L 9/3268
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for modifying an electronic device ( 10 ) using authenticated data from a data host ( 12 ) comprises the steps of the a signing service ( 13 ) digitally signing the data with a digital signature using a signature private key of a signature key pair and providing the signed data to the data host ( 12 ), the electronic device ( 10 ) retrieving the signed data from the data host ( 12 ), the electronic device ( 10 ) confirming a signature public key of the signature key pair using a certificate of a certificate authority ( 14 ), the electronic device ( 10 ) checking whether the certificate is valid, and the electronic device ( 10 ) confirming the digital signature and thus authenticity of the data using the signature public key. The certificate includes an iteration number, and the electronic device ( 10 ) checks whether the certificate is valid based on the iteration number.

Claims

exact text as granted — not AI-modified
1 . A method for modifying an electronic device using authenticated data from a data host, the method comprising the steps of
 a signing service digitally signing the data with a digital signature using a signature private key of a signature key pair and providing the signed data to the data host;   the electronic device retrieving the signed data from the data host;   the electronic device confirming a signature public key of the signature key pair using a certificate of a certificate authority;   the electronic device checking whether the certificate is valid; and   the electronic device confirming the digital signature and thus authenticity of the data using the signature public key,   
       wherein the certificate includes an iteration number and in that the electronic device checks whether the certificate is valid based on the iteration number. 
     
     
         2 . The method according to  claim 1 ,
 wherein at least a second digital signature and at least a second certificate are used to confirm authenticity of the data, with the second certificate also checked for validity based on the iteration number or another iteration number.   
     
     
         3 . The method according to  claim 1 ,
 wherein the electronic device stores a minimal iteration number that the certificate's iteration number needs to match or exceed in order to be accepted as being valid.   
     
     
         4 . The method according to  claim 1 ,
 wherein certificates of the certificate authority are validated by a chain of higher-level certificate authorities with a root certificate authority at the origin of the chain, wherein in particular the electronic device stores a root certificate of the root certificate authority.   
     
     
         5 . The method according to  claim 1 ,
 wherein the electronic device stores a product identifier corresponding to a designated certificate authority among a plurality of certificate authorities that include a certificate authority responsible for each possible product identifier.   
     
     
         6 . The method according to  claim 5 ,
 wherein the electronic device ( 10 ) checks whether the certificate matches the product identifier.   
     
     
         7 . The method according to  claim 5 ,
 wherein the root certificate authority authenticates a plurality of certificate authorities that include a certificate authority responsible for each possible product identifier.   
     
     
         8 . The method according to  claim 1 ,
 wherein, in order to invalidate or revoke a certificate, a new certificate authority is set up, replacing the certificate authority, and issuing certificates with iteration number increased.   
     
     
         9 . The method according to  claim 8 ,
 wherein the new certificate authority is authenticated by the root certificate authority.   
     
     
         10 . The method according to  claim 9 ,
 wherein the authentication by the root certificate authority takes place offline and/or wherein the root certificate authority is always offline.   
     
     
         11 . The method according to  claim 8 ,
 wherein, following revocation of a certificate and increase of the iteration number, the electronic device is updated via authenticated data retrieved from the data hos), the update including storage of a new minimal iteration number.   
     
     
         12 . A data host and certification network for providing authenticated data to an electronic device, the certification network comprising a certificate authority configured to issue a certificate confirming authenticity of a signature public key of a signature key pair and a signing service for digitally signing the data with a digital signature using a signature private key of the signature key pair and the data host providing direct or indirect access for the electronic device to retrieve the signed data, wherein the certificate includes an iteration number usable in a check whether the certificate is valid. 
     
     
         13 . An electronic device comprising an interface for at least indirectly connecting the electronic device to a data host, a memory for storing data, and a control unit configured to
 retrieve authenticated data via the interface and to store the data in the memory, the data digitally being signed by a signing service with a digital signature using a signature private key of a signature key pair;   verify a signature public key of the signature key pair using a certificate of a certificate authority;   check whether the certificate is valid;   confirm the digital signature and thus authenticity of the data using the signature public key; and   if authenticity of the data is confirmed, modify the future control of the electronic device based on the data,   wherein the certificate includes an iteration number and the control unit is further configured to check whether the certificate is valid based on the iteration number.   
     
     
         14 . An electronic device according to  claim 13  that is configured as a sensor. 
     
     
         15 . A system comprising at least one data host and certification network according to  claim 12  and at least one electronic device according to  claim 13 .

Join the waitlist — get patent alerts

Track US2024333529A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.